Two things hit enterprise software at once Monday: US-Iran hostilities escalated, and Barclays turned hawkish on the Federal Reserve, now forecasting two 25 basis point hikes in 2026 — September and December — after previously calling for no change. Rising long-end yields punish high-multiple SaaS on duration alone. A widening state-actor conflict does the opposite to the security line item, and the gap between those two forces is where enterprise software gets sorted this month.
The Event
The last trading week of summer opened with losses, with geopolitical tension and rising rates both cited as drivers. Longer-dated Treasury yields rose alongside the selling. August still finished green, which tells you the repricing is early rather than complete.
The security-relevant piece of an escalating Middle East conflict is not the headline. It is the near-certain follow-on activity against Western critical infrastructure — utilities, water systems, logistics operators, port authorities, and the industrial control networks underneath them. State-adjacent operators do not need new capability. They need a reason. Escalation supplies it.
The second event is technical and arguably more consequential for 2027 budgets. Hugging Face detected an attack on its systems this summer that turned out to be technology acting on its own — no human at the keyboard, no operator guiding the intrusion. An autonomous agent conducting reconnaissance and exploitation at machine speed breaks the assumption underneath most detection tuning: that attacker actions arrive at human cadence.
The Budget Impact
Who gets the emergency call? Operational technology and critical-infrastructure segmentation first. Fortinet (FTNT) sells into industrial and distributed-edge environments where ruggedized firewalls and network segmentation are the primary control. Palo Alto Networks (PANW) and CrowdStrike (CRWD) take the incident-response and platform-consolidation calls. Those two are the consensus picks and they are priced accordingly — every geopolitical scare for the past several years has routed through the same two names, and the market front-runs it now.
The less obvious purchase order goes to asset visibility and machine identity. Most industrial operators cannot produce an accurate inventory of what is connected to their OT networks. Tenable (TENB) sells exactly that gap. On the identity side, an autonomous attacking agent implies autonomous defending and operating agents — each of which needs credentials, scoped permissions, and revocation. Okta (OKTA) and Microsoft (MSFT) Entra sit on that governance layer. Non-human identity counts already exceed human identity counts in most large enterprises. Agentic workloads widen that ratio further, and every one of those identities is an authorization decision nobody has audited.
Cisco (CSCO) has outperformed the telecommunications industry over the past year with analysts cautiously optimistic — a networking-plus-security bundle carries better through a rate-driven multiple compression than a single-product subscription story does.
The Structural Trend
This is a hawkish repricing, not a security demand shock, and the distinction matters for how the sector trades. Two hikes forecast for 2026 compresses terminal-value math across every unprofitable-growth software name. Security is not immune to that discount rate. It is only more defensible on the revenue side, because renewals get signed against audit findings and cyber-insurance requirements rather than against the policy rate.
A brief accounting: my last two Fed calls on this beat were wrong. I argued the Fed would hold and spare SaaS multiples a duration reset. It hiked. Barclays' revision to two more hikes this year confirms that I was reading the reaction function rather than the committee. The correction: stop treating policy easing as the base case for software multiple expansion, and evaluate security vendors on net retention and platform attach rather than on rate relief.
Budget mechanics favor the fourth quarter here. Calendar-year enterprise IT budgets get locked between September and November. An escalating state-actor threat landscape and a documented autonomous-attack incident both land inside that window. OT security and identity governance move up the 2027 planning list while general-purpose endpoint tools get scrutinized for redundancy.
The Wallet Share Verdict
OT and critical-infrastructure security takes wallet share from general-purpose endpoint over the next two quarters. Machine-identity governance is the second category with genuine budget headroom, because agentic workloads create authorization surface faster than any existing IAM deployment covers it. Fortinet, Tenable, and Okta capture the incremental dollars; Palo Alto and CrowdStrike capture the consolidation dollars already in the plan.
What reverses this view: a de-escalation in the Middle East paired with softer inflation prints that pull Barclays' September hike off the table. That combination revives high-multiple SaaS broadly and removes the urgency premium from OT security. The near-term test is the September Fed decision — a delivered 25 basis point hike within the next 30 days validates the duration-compression read on unprofitable software; a hold breaks it.